CVE-2024-38428

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
mitreCNA
---
---
CISA-ADPADP
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
gnuwget
𝑥
≤ 1.24.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
wget
bullseye
vulnerable
buster
postponed
bullseye (security)
1.21-1+deb11u2
fixed
bookworm
1.21.3-1+deb12u1
fixed
sid
1.25.0-2
fixed
trixie
1.25.0-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
wget
plucky
Fixed 1.24.5-1ubuntu2
released
oracular
Fixed 1.24.5-1ubuntu2
released
noble
Fixed 1.21.4-1ubuntu4.1
released
mantic
Fixed 1.21.3-1ubuntu1.1
released
jammy
Fixed 1.21.2-2ubuntu1.1
released
focal
Fixed 1.20.3-1ubuntu2.1
released
bionic
Fixed 1.19.4-1ubuntu2.2+esm1
released
xenial
Fixed 1.17.1-1ubuntu1.5+esm1
released
trusty
needs-triage